
IT Security Analyst
- Timișoara, Timiș
- Permanent
- Full-time
- You will read and understand regular vulnerability assessments and penetration testing on applications to identify security flaws (e.g. Rapid7).
- You will manage and operate application security tools, including Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) solutions.
- You will collaborate with development teams to embed security into the SDLC (Software Development Lifecycle), providing guidance on secure coding practices and threat modeling.
- Overseeing the entire lifecycle of vulnerability management, from discovery and analysis to remediation and verification.
- You will develop, manage, and execute a comprehensive patch management program for all operating systems, applications, and infrastructure components, ensuring timely deployment and compliance.
- Tracking and reporting on key metrics for vulnerability and patch management, providing clear visibility of our security posture to stakeholders.
- You will develop and enforce security policies and standards for all IoT and connected devices, including device onboarding, authentication, and data encryption.
- Performing security assessments of new and existing IoT deployments to identify and mitigate risks.
- You will administer and secure our wireless infrastructure, including conducting regular Wi-Fi security audits, configuring WPA3/WPA2-Enterprise, and detecting rogue access points.
- Harden network devices (routers, switches, firewalls) by implementing secure configurations, managing access controls, and monitoring for anomalous activity.
- Segment the network to isolate critical systems, applications, and IoT devices, minimizing the potential impact of a security breach.
- Monitoring network traffic for signs of intrusion and respond to security alerts related to network infrastructure.
- You will act as a key member of the IT Support team, assisting in the analysis, containment, and eradication of security incidents.
- work in a multicultural environment and handle activities based on tickets using ITIL best practices.
- Staying current with the latest cybersecurity threats, vulnerabilities, and industry best practices to continuously improve our security posture.
- You will develop and maintain clear documentation for security processes, procedures, and system configurations.
- You will assist in compliance audits by providing evidence of security controls and measures.
- Experience: 2+ years of experience in an IT security role, with at least 1 year focused on application security, vulnerability management, and network security.
- Application Security: Proven experience with application vulnerability scanning tools (e.g. Checkmarx).
- Patch Management: Demonstrable experience managing a corporate-wide patch management program using tools like WSUS or other third-party solutions.
- Network Security: In-depth knowledge of network protocols, firewall management, IDS/IPS, and VPN technologies. Hands-on experience securing Cisco, Palo Alto, or similar network hardware.
- Wi-Fi Security: Strong experience with enterprise wireless security standards (802.1X, EAP-TLS, WPA3) and tools for wireless network monitoring.
- IoT Security: Good understanding of the security challenges associated with IoT devices and experience implementing security controls for them.
- Operating Systems: Proficiency in securing both Windows and Linux server/client environments.
- Certifications: Professional security certifications is an advantage.
- Scripting: Proficiency in a scripting language (e.g., Python, PowerShell) for automating security tasks.
- Cloud Security: Basic experience with securing cloud environments (AWS, Azure) is a plus.
- Education: Bachelor's degree in Computer Science, Information Security, or a related field.
- Analytical Mindset: Strong analytical and problem-solving skills with meticulous attention to detail.
- Communication: Excellent written and verbal communication skills, with the ability to explain complex technical concepts to both technical and non-technical audiences.
- Collaboration: A proactive and collaborative team player who can work effectively with cross-functional teams.
- Self-Motivated: Ability to work independently, manage priorities, and take ownership of projects from start to finish.
- An environment where you will feel fulfilled by your work, valued for your contribution and celebrated for your success;
- Opportunities to learn new skills in a multi-field industry (Automotive, Lifestyle, Healthcare, Industrial, Communications);
- Customized career paths based on your aspirational goals.
- A competitive salary and benefits package that includes:
- A merit-based pay and living-adjustments;
- Holiday bonus;
- Performance bonus;
- Loyalty bonus;
- Reward and recognition bonus;
- Referral bonus;
- Flexible/Remote/Hybrid Work based on your Job Function;
- Travel opportunities;
- Support in your wellbeing by access to:
- Private medical/ pension insurance;
- Free workshops and seminars on well-being;
- Free access to therapy and consultations;
- Having fun at work;
- Community experiences and events for you and your children;
- Access to various discounts programs (shopping, food&drink, sport).